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Q. Other than those two scenarios is there -- 


strike that. How did you determine that you wanted to 
review additional documents? 

Au Any additional documents that I would have 
reviewed would have been I believe we discussed this at 
my last deposition entering search terms on Relativity 
or performing searches across the files. 

Q. So would it be fair to say that your previous 
testimony in your previous deposition as to how you 
determined what documents to look at it was the same 
procedure for your most recent report which is Exhibit 
a2 

Rus Yes. I believe that's fair to say. 

Os I was just trying to understand. I 
understand, thank you. Now, again under Appendix A in 
Exhibit 3 there is a column that says native hash. Do 


you see that? 


As It says native file hash. 

Q. Native file hash, thank you. What does that 
mean? 

A. Native file hash is a cryptographic hash in 


this case an MD5 hash of the native files that I 
reviewed. 
on Now, my question is at what point in time -—- 


who generated those native hashes? 
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A. The native file hashes listed in my report I 
dad. 
0. When did you generate those hashes? 
A. At variety points in time between my first 


report and my third report. 

on Okay, but now my question is why was it at 
various points in time? 

A. Because as I said before I didn't review every 
Single document at once. I was provided certain 


document over time and once I reviewed them of course I 





would hash them. 
O. SO 2S 10 fair to say that —- so you have a 


document you're about to review it. At what point in 





time do you generate the hash? 
A. So typically I would generate a hash prior to 
reviewing the file and then hash the file again after 


reviewing it to make sure that the hashes are the same. 





Os And what you're saying right here the native 





file hash you recorded the hash that you generated at 
that point in time? 

A. Yes. 

Q. And so really it's -- I assume if there's only 
one hash that's because it was the same hash before and 
after you analyzed the document? 


MR. ROCHE: Objection, form. 
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THE WITNESS: Yes. 
MR. ROCHE: Zalman, can we take a break 
sometime within the next five minutes? 
MR. KASS: Sure. Just one more question. 
We're getting close to a break time. 
BY MR. KASS 
Q. Now, this list of documents considered what 


the hash is are these solely documents in your most 





recent report which is Exhibit 3? 


A. No. 

O. So these are also documents that are in other 
reports? 

A. Yes. 

Os Now it's my understanding that you did not 


record the hash values previously; is that correct? 


A. No. 
O. You're saying you did record the hash values? 
A. At least I hashed the documents. I didn't 


provide them in my previous reports. 

Q. So your -- I want to make sure I understand 
your testimony is that you had hashed the documents for 
when you're doing your analysis for Exhibit 1 and 
Exhibit 2; correct? 

A. Yes, I had hashed the documents. 


Q. And that you had recorded the actual hash 
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uy can answer. 
2 THE WETNESS: I think 1t*s fair to say. 
S MR. KASS: Kyle, that is all I have. I don't 
4 know if you have anything. 
5 MR. ROCHE: I have just a few quick questions. 
6 Ready? 
Fi MR. KASS: Give me one quick second. I want 
8 to shuffle my desk. 
7 CROSS (DR. MATTHEW EDMAN) 
10 BY MR. ROCHE 
11 Q. Good afternoon, Dr. Edman. Just have a few 
12 quick questions for you. When Mr. Kass was asking you 
13 questions related to cryptographic hashes on certain 
14 document you analyzed. Do you recall that line of 
15 questioning? 
16 MR. KASS: Object to the form. 
17 THE WITNESS: I recall we were discussing 
13 certain cryptographic signatures which do contain 
is cryptographic hashes. We also discussed 
20 cryptographic hashes of native files that I 
aA. reviewed. 
22 BY MR. ROCHE 
23 Q. Is SHA-256 an example of a cryptographic hash? 
24 A. Tes. 
25 MR. KASS: So Kyle, I'm objecting to the 
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extent you're going outside the scope of his 
opinion. Just putting it here. We'll see how far 
you go. 
MR. ROCHE: Understood. 
BY MR. ROCHE 
en Is it your expert opinion -- in your expert 
opinion are SHA-256 outputs evenly distributed? 
MR. KASS: Object. Kyle, this goes outside 
the scope of Dr. Edman's disclosed opinion. 
MR. ROCHE: Understood. 
THE WITNESS: Assuming unique inputs the 
QUEDUE Of cryptographic funclion such as SHA—-256 as 
generally uniformly distributed. 
MR. ROCHE: No further questions. 
REDIRECT (DR. MATTHEW EDMAN) 
BY MR. KASS 


Os Dr. Edman, when you state generally uniformly 





distributed why do you have that qualifier over there? 

Pe Perhaps there is a cryptographic hash that I'm 
not aware of where the outputs are not uniformly 
distributed but I'm not sure what good that would be. 

Q. Did you do any testing of SHA-256 hash to see 
if it is in fact uniformly distributed? 

A. That's certainly been my experience and that's 


my understanding of others analysis of cryptographic 
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hash functions as SHA-1, SHA-256, SHA-12 and so on. 


Oe My question is did you do any specific testing 


to confirm that? 


A. Me personally? 
Q. Yes. 
A. No. 
MR. KASS: Kyle? 
MR. ROCHE: No further questions. 
THE WITNESS: Is that it? 
MR. KASS: That is it. 
MR. ROCHE: We're off the record. 
MR. KASS: Rick, we're going to ask for it as 


soon as possible. 


(Witness excused.) 


(Deposition was adjourned.) 
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